Introduction

In line with the directives of the Kingdom of Saudi Arabia to enhance the value of national data, consolidate governance principles, improve information asset management efficiency, and in accordance with the National Data Governance Guide issued by the National Data Management Office (NDMO), Najran University has issued this policy to regulate the management of content and documents..

This policy aims to establish a comprehensive governance framework for the management of documents and content in all their forms, both paper and digital, ensuring their integrity, quality, accessibility, protection from risks, and regulation of their lifecycle from creation or receipt until archiving, destruction, migration, or disposal, in accordance with approved regulatory controls.

The purpose of policy

This policy aims to organize and manage the content and documents of Najran University in a way that achieves the following:

  • Alignment with the National Data Governance Guide (NDMO) and application of its institutional requirements.
  • Supports the achievement of Vision 2030 targets in digital transformation, governance, and transparency..Guaranteed by the Systematic Management Cycle of Documents and Content.Enhancing the participation of data and general information in accordance with regulatory frameworks.Protection of Personal Data and Sensitive Data and Ensuring Their Confidentiality.Preserve the university’s and individuals' rights and intellectual property.
  • Enhancing Confidence in Data-Driven Services.
  • Enhancing Integration between Governmental BodiesSupport integrity and combat corruption by providing public information in accordance with regulations..

Application Scope

This policy applies to all sectors and units of Najran University, and to all documents, content, data that the University creates, receives, processes, stores, or archives, regardless of its form, medium, or source, unless a specific exemption is stated.

Guiding Principles

The management of content and documentation at the University is subject to the following principles

  • Responsibility and Ownership:: Clear definition of document ownership and responsibilities for its administration.
  • Quality and Reliability: Ensuring the accuracy, integrity, and completeness of documents.
  • Classification and Protection: Classification of documents according to levels of confidentiality and sensitivity.Continuity

    :

    ensures the availability of documents and their protection from loss or damage

    .

Lifecycle Document Management Framework

Includes the stages and requirements of document lifecycle management as follows:

  1. Creating and Naming Documents
    • Commitment to a unified and approved naming convention for documents at the university level.
    Include the basic data of the document when it is created, which includes – as a minimum: - Document identifier, version number, date of creation or update, document owner, responsible party, and document status.

    1. البيانات الوصفية(Metadata)
  1. Creating mandatory descriptive data for documents according to the standards approved by the National Data Management Office (NDMO).
  • Continuous metadata updates throughout the document lifecycle, reflecting any changes to content, classification, or permissions..
    1. Document Classification
      • Document classification according to retention period: (Permanent, Temporary), in accordance with approved retention schedules.
      Classification of Documents According to Confidentiality Level: (Highly Secret, Secret, Restricted, Public).
    1. Review the classification periodically or when there is a fundamental change in the content or its sensitivity.
      1. Access and Usage
        • Regulation of Access and Usage Categories according to Approved Authorities and the Principle of Minimum Privileges.
      Restricting access to sensitive or protected documents, and documenting any modifications to permissions in accordance with approved procedures.

      1. Backup and Restore
        • Regular backups of documents should be performed according to defined levels (daily, weekly, monthly) based on their classification and importance
    2. Conduct periodic retrieval tests to verify the integrity of backups and the effectiveness of recovery procedures..
      1. The Archiving and Migration
        • Compliance with the regulations and instructions of the National Archives and Documentation Center in archiving and migration operations..
      1. Utilizing approved Content Management and Electronic Document Systems to ensure the preservation of documents, track versions, and document procedures.
        1. Damaging documents that have expired from their retention periods in accordance with the approved official procedures, after completing the necessary approvals.
      2. Documentation of damages and their records to ensure transparency and accountability
    Roles and Responsibilities

    Roles and responsibilities are defined according to the governance model specified in the guidance document of the National Data Office (NDMO), and the regulations of the National Archives and Documentation Center, ensuring a separation of roles and accountability as follows:

    The Party

    The Roles and Responsibilities

    The Supreme Council Committee for Data Management and Governance

    Approval of the Policy

    Supervision of the implementation of this policy.

    Data Management Office

    Supervision of the implementation of this policy and monitoring compliance with it.

    Monitoring compliance with data classification guidelines, access, and data quality.

    Coordination with the National Archives and Documentation Center and related parties.

    Data Steward

    The creation and update and management of descriptive data. Metadata for documents.

    Data quality, accuracy, completeness, and consistency.Coordinate with the Data Management Office throughout the document lifecycle.

    Support for Compliance with Governance and Accreditation Requirements

    Documents and Archives Center / Archiving Manager

    Application of the regulations and instructions of the National Archives and Documents Center.

    Preparation and implementation of authorized document archiving lists.

    Preserve and archive active, inactive, and intermediate documents.

    Implementation of procedures for relocation and systematic destruction of documents.

    Guarantee the safety of archival documents and digital copies..

    College of Digital Transformation and Knowledge Sources

    Operation and maintenance of content management systems and electronic document management.

    Implementing backups and restores in accordance with approved guidelines.

    Guarantee the integrity of systems and business continuity.

    Support initiatives to transition from paper documents to digital ones.

    Legal Department

    Review the relevant policies and procedures from a regulatory perspective.

    Guarantee of compliance with relevant regulations, including the protection of personal data and the right to access information.

    Legal consultations and handling complaints related to documents and information.

    Cybersecurity Management

    Applying Cybersecurity Controls to Document Management Systems.

    Protecting classified documents and sensitive data as well as personal information.

    Risk assessment of disclosure or publication and ensuring that the University is not exposed to cyber risks.

    All administrative units and university personnel

    Compliance with the terms of this policy and associated instructions.

    Use documents and content according to authorized privileges only.

    Compliance and Oversight

    All members of the University are committed to the provisions of this policy.

    The Data Management Office will be responsible for monitoring compliance and submitting periodic reports.

    Review of the policy

    The Data Management Office will review this policy periodically and update it in accordance with updates issued by NDMO and the National Archives and Documentation Center.